Question

Difficulty: HardTroubleshooting Mobile OS Security and Connectivity Issues

An IT security administrator notices that several enterprise mobile devices are failing to authenticate against the corporate 802.1X wireless network and displaying untrusted server certificate warnings when browsing internal HTTPS portals. Further inspection reveals an unauthorized configuration profile was secretly installed alongside a side-loaded utility application. Which TWO of the following troubleshooting and remediation steps should the administrator take to resolve these security and connectivity issues?

  1. Remove the malicious configuration profile from the mobile device settings.Answer
  2. B
    Initiate a cellular network master reset with the mobile service provider.
  3. Re-enroll the affected devices into the enterprise MDM server to push verified security certificates.Answer
  4. D
    Downgrade the corporate Wi-Fi access points to use WPA2-Personal with a pre-shared key (PSK).
  5. E
    Disable the Application Installation permissions globally across the operating system via developer options.

Answer

The administrator must remove the malicious configuration profile from the mobile device settings and re-enroll the affected devices into the enterprise MDM server.
Deleting the unauthorized configuration profile removes untrusted root certificates and proxy settings causing browser warnings and authentication failures. Re-enrolling the device in MDM automatically restores corporate 802.1X wireless profiles and legitimate security certificates.

Step-by-Step Solution

1
Locate and inspect installed profiles in device settings.
Identify the rogue configuration profile containing untrusted root certificates and proxy configurations.
Unauthorized profiles alter mobile OS trust stores and network routing parameters.
2
Delete the malicious configuration profile.
Purge untrusted certificates and rogue network redirects from the device.
Removing the profile eliminates active man-in-the-middle trust violations and unauthorized traffic redirection.
3
Re-enroll the device in enterprise Mobile Device Management (MDM).
Deploy compliant network profiles, valid 802.1X credentials, and official corporate CA certificates.
MDM re-enrollment restores verified Wi-Fi authentication configurations necessary for secure 802.1X enterprise connection.

Key Concept

Remediating Mobile OS Security Profiles and 802.1X Wireless Authentication
Rate this question